Sample
- SHA256
-
ed7a360f6e983587c4fa7da124a3ce847a963cc1352322405cf50171cc94c247 - Difficulty
- easy
- Platform
- Windows
- Tags
- legion ransomware
- Likes
- 0
- Views
- 7
- Submitter
- struppigel
Analysis
Goal
Find the encryption procedure of this sample and determine how the files that were encrypted by this ransomware can be decrypted.
To do that you may also have to patch the sample, to make it run on your system.
Description
legionsample.zip contains the ransomware binary. Follow the videos in the course and learn how to find the location of encryption algorithms in ransomware and how to analyze them.
Recommended Tools
Ghidra ProcMon x64dbg
Comments
Please login to view and post comments.